The Feral Wolf ransomware group has been actively targeting Russian organizations by exploiting exposed Confluence servers, insecure 1C configurations, and compromised contractors, ultimately deploying the GenieLocker ransomware. This campaign notably leveraged the Atlassian Confluence vulnerability CVE-2023-22515, based on information published by Smarter MSP.Feral Wolf is a financially motivated threat actor known for exploiting enterprise systems, weak configurations, and vulnerable software. The group conducts thorough reconnaissance, establishes covert access, and employs anti-forensic tools to erase logs and hinder investigations. They route command-and-control traffic through MQTT, Matrix, and RDP-based tunnels to evade detection. The attack chain often begins with the exploitation of CVE-2023-22515 in Confluence, followed by privilege escalation using CVE-2021-4034 and CVE-2026-31431.Weakly secured 1C:Enterprise systems and compromised credentials further facilitate network-wide compromise. A successful attack can lead to significant business disruption, data encryption, and extended recovery periods. Recommendations include patching Confluence and Linux kernels, enforcing strong authentication, and isolating administrative interfaces and services from direct internet exposure.Source: Smarter MSP